Re: Best way to decrease DDoS with pf.

2007-05-19 Thread Kian Mohageri
On 5/18/07, Abdullah Ibn Hamad Al-Marri <[EMAIL PROTECTED]> wrote: On 5/19/07, Kian Mohageri <[EMAIL PROTECTED]> wrote: > On 5/18/07, Abdullah Ibn Hamad Al-Marri <[EMAIL PROTECTED]> wrote: > > On 5/18/07, Kian Mohageri <[EMAIL PROTECTED]> wrote: > > > On 5/18/07, Abdullah Ibn Hamad Al-Marri <[EMA

Re: Best way to decrease DDoS with pf.

2007-05-18 Thread Abdullah Ibn Hamad Al-Marri
On 5/19/07, Kian Mohageri <[EMAIL PROTECTED]> wrote: On 5/18/07, Abdullah Ibn Hamad Al-Marri <[EMAIL PROTECTED]> wrote: > On 5/18/07, Kian Mohageri <[EMAIL PROTECTED]> wrote: > > On 5/18/07, Abdullah Ibn Hamad Al-Marri <[EMAIL PROTECTED]> wrote: > > > On 5/18/07, Kian Mohageri <[EMAIL PROTECTED]>

Re: Best way to decrease DDoS with pf.

2007-05-18 Thread Kian Mohageri
On 5/18/07, Abdullah Ibn Hamad Al-Marri <[EMAIL PROTECTED]> wrote: On 5/18/07, Kian Mohageri <[EMAIL PROTECTED]> wrote: > On 5/18/07, Abdullah Ibn Hamad Al-Marri <[EMAIL PROTECTED]> wrote: > > On 5/18/07, Kian Mohageri <[EMAIL PROTECTED]> wrote: > > > On 5/18/07, Abdullah Ibn Hamad Al-Marri <[EMA

Re: Best way to decrease DDoS with pf.

2007-05-18 Thread Abdullah Ibn Hamad Al-Marri
On 5/18/07, Kian Mohageri <[EMAIL PROTECTED]> wrote: On 5/18/07, Abdullah Ibn Hamad Al-Marri <[EMAIL PROTECTED]> wrote: > On 5/18/07, Kian Mohageri <[EMAIL PROTECTED]> wrote: > > On 5/18/07, Abdullah Ibn Hamad Al-Marri <[EMAIL PROTECTED]> wrote: > > > Thank you for the tip. > > > > > > Here what

Re: Best way to decrease DDoS with pf.

2007-05-18 Thread Kian Mohageri
On 5/18/07, Abdullah Ibn Hamad Al-Marri <[EMAIL PROTECTED]> wrote: On 5/18/07, Kian Mohageri <[EMAIL PROTECTED]> wrote: > On 5/18/07, Abdullah Ibn Hamad Al-Marri <[EMAIL PROTECTED]> wrote: > > Thank you for the tip. > > > > Here what I'm using which fixed the issue. > > > > pass in on $ext_if pro

Re: Best way to decrease DDoS with pf.

2007-05-18 Thread Abdullah Ibn Hamad Al-Marri
On 5/18/07, Drew Tomlinson <[EMAIL PROTECTED]> wrote: On 5/18/2007 9:54 AM Abdullah Ibn Hamad Al-Marri said the following: > On 5/18/07, Kian Mohageri <[EMAIL PROTECTED]> wrote: > >> On 5/18/07, Abdullah Ibn Hamad Al-Marri <[EMAIL PROTECTED]> wrote: >> > Thank you for the tip. >> > >> > Here wha

Re: Best way to decrease DDoS with pf.

2007-05-18 Thread Drew Tomlinson
On 5/18/2007 9:54 AM Abdullah Ibn Hamad Al-Marri said the following: On 5/18/07, Kian Mohageri <[EMAIL PROTECTED]> wrote: On 5/18/07, Abdullah Ibn Hamad Al-Marri <[EMAIL PROTECTED]> wrote: > Thank you for the tip. > > Here what I'm using which fixed the issue. > > pass in on $ext_if proto tcp

Re: Best way to decrease DDoS with pf.

2007-05-18 Thread Abdullah Ibn Hamad Al-Marri
On 5/18/07, Kian Mohageri <[EMAIL PROTECTED]> wrote: On 5/18/07, Abdullah Ibn Hamad Al-Marri <[EMAIL PROTECTED]> wrote: > Thank you for the tip. > > Here what I'm using which fixed the issue. > > pass in on $ext_if proto tcp from any to $ext_if port $tcp_services > flags S/SA synproxy state > pas

Re: Best way to decrease DDoS with pf.

2007-05-18 Thread Kian Mohageri
On 5/18/07, Abdullah Ibn Hamad Al-Marri <[EMAIL PROTECTED]> wrote: Thank you for the tip. Here what I'm using which fixed the issue. pass in on $ext_if proto tcp from any to $ext_if port $tcp_services flags S/SA synproxy state pass in on $ext_if proto tcp from any to $ext_if port $tcp_services

Re: Best way to decrease DDoS with pf.

2007-05-18 Thread Abdullah Ibn Hamad Al-Marri
On 5/18/07, Volker <[EMAIL PROTECTED]> wrote: > This isn't bandwidth issue, but filling the network buffer more than > anything else, so there are no more free sockets, and I can't connect > to the server via ssh, it's not syn as well. > > But mass connect to IRC server with small bw, and the ser

Re: Best way to decrease DDoS with pf.

2007-05-18 Thread Volker
> This isn't bandwidth issue, but filling the network buffer more than > anything else, so there are no more free sockets, and I can't connect > to the server via ssh, it's not syn as well. > > But mass connect to IRC server with small bw, and the server isn't > lagged at all. > > Rate: 245,919 P

Re: Best way to decrease DDoS with pf.

2007-05-17 Thread Kian Mohageri
On 5/17/07, Abdullah Ibn Hamad Al-Marri <[EMAIL PROTECTED]> wrote: Hello, This isn't bandwidth issue, but filling the network buffer more than anything else, so there are no more free sockets, and I can't connect to the server via ssh, it's not syn as well. But mass connect to IRC server with s

Best way to decrease DDoS with pf.

2007-05-17 Thread Abdullah Ibn Hamad Al-Marri
Hello, This isn't bandwidth issue, but filling the network buffer more than anything else, so there are no more free sockets, and I can't connect to the server via ssh, it's not syn as well. But mass connect to IRC server with small bw, and the server isn't lagged at all. Rate: 245,919 Packets